A heap overflow vulnerability has been discovered in all versions of rsync prior to 2.5.7. This vulnerability, exploitable when rsync is being run in "server mode", may allow the attacker to run arbitrary code on the compromised server.